[!IMPORTANT]
This is the single pane of glass for HIPAA compliance at Cytognosis Foundation.
Every control links to its evidence document. Update this file whenever a control
is activated or its status changes.
| Category | Done | Pending | Deferred | Total |
|---|---|---|---|---|
| Administrative Safeguards | 8 | 3 | 0 | 11 |
| Physical Safeguards | 3 | 0 | 0 | 3 |
| Technical Safeguards | 10 | 1 | 0 | 11 |
| Organizational | 3 | 0 | 0 | 3 |
| Policies & Procedures | 8 | 2 | 0 | 10 |
| TOTAL | 32 | 6 | 0 | 38 |
All physical safeguards are inherited from GCP. GCP is certified ISO 27001, SOC 2 Type II,
and operates HIPAA-aligned facilities. Cytognosis does not maintain its own data center.
| Control | Status | Evidence | Owner |
|---|---|---|---|
| Facility access controls (physical) | ✅ Done (inherited) | GCP HIPAA Implementation Guide | GCP |
| Workstation use policy | ✅ Done | Data governance policy §Workstations | Shahin Mohammadi |
| Device and media controls | ✅ Done | Data governance policy §Devices | Shahin Mohammadi |
allServices on both infra + phi-prod; GCP audit | Shahin Mohammadi |
| 7-year audit log retention | ✅ Done | gs://cytognosis-audit-7yr | Shahin Mohammadi |
| Audit log retention locked (irrevocable) | ✅ LOCKED 2026-05-22 | audit-log-retention.md | Shahin Mohammadi |
| Log tampering prevention | ✅ Done | Locked retention policy | Shahin Mohammadi |
phi-core + phi-collab-nih; GCP audit | Shahin Mohammadi |
| Control | Status | Evidence | Owner |
|---|---|---|---|
| BAA with GCP signed | ✅ Done | Accepted 2025-09-01 | Shahin Mohammadi |
| Written BAA requirements for all BAs | ✅ Done | baa-inventory.md | Shahin Mohammadi |
| Covered entity status documented | ✅ Done | hipaa-compliance-framework.md §Covered Entity | Shahin Mohammadi |
| Control | Status | Evidence | Owner |
|---|---|---|---|
| HIPAA compliance framework policy | ✅ Done | hipaa-compliance-framework.md | Shahin Mohammadi |
| Data governance policy | ✅ Done | ../policies/data-governance-policy.md | Shahin Mohammadi |
| Controlled data access policy | ✅ Done | ../policies/controlled-data-access.md | Shahin Mohammadi |
| NIH NDA access procedures | ✅ Done | ../policies/nih-nda-access-procedures.md | Shahin Mohammadi |
| Privacy Impact Assessment template | ✅ Done | pia-template.md | Shahin Mohammadi |
| Risk Assessment template | ✅ Done | risk-assessment-template.md | Shahin Mohammadi |
| Deferred controls register | ✅ Done | deferred-controls.md | Shahin Mohammadi |
| Member-inference evaluation methodology | ✅ Done | member-inference-eval.md | Shahin Mohammadi |
| Annual policy review cadence documented | ✅ Done | Deferred controls §Review Schedule | Shahin Mohammadi |
| Policy documentation retention | ⏳ Pending — define retention | — | Privacy Officer (TBD) |
NIH GDS Best Practices (2025, effective for new/renewed DUCs after 2025-01-25) require
NIST SP 800-171 compliance. See full breakdown in
nih-gds-requirements.md.
| Control | Status | Notes |
|---|---|---|
| NIST SP 800-171: Access control (AC) | ⏳ Gap assessment needed | Pre-DUC; no controlled data yet |
| NIST SP 800-171: Audit & accountability (AU) | ✅ Done | Audit logs + Data Access audit logging (allServices) enabled 2026-05-26 |
| NIST SP 800-171: Configuration management (CM) | ⏳ Gap assessment needed | IaC (container framework) exists; formal CM policy missing |
| NIST SP 800-171: Identification & authentication (IA) | ✅ Done | MFA via Google Workspace; OIDC federation |
| NIST SP 800-171: Incident response (IR) | ✅ Done | Runbook in place |
| NIST SP 800-171: Maintenance (MA) | ⏳ Not documented | — |
| NIST SP 800-171: Media protection (MP) | ⏳ Not documented | No physical media; cloud only |
| NIST SP 800-171: Personnel security (PS) | ⏳ Partial | Training program defined; not yet run |
| NIST SP 800-171: Physical protection (PE) | ✅ Done (inherited) | GCP facilities |
| NIST SP 800-171: Risk assessment (RA) | ✅ Done | Template + initial assessment |
| NIST SP 800-171: Security assessment (CA) | ⏳ Not yet | Pre-DUC; do before first DUC submission |
| NIST SP 800-171: System comms protection (SC) | ✅ Partial | TLS everywhere; VPC-SC deferred |
| NIST SP 800-171: System & information integrity (SI) | ✅ Partial | Audit logs; CVE scanning not yet |
| Countries of concern restriction (NOT-OD-25-083) | ⏳ Policy needed | Prohibits access from countries of concern |
| Generative AI restriction (2025 GDS update) | ✅ Documented | See nih-gds-requirements.md §7 |
[!IMPORTANT]
Before submitting the first NDA/dbGaP/Synapse DUC, a formal NIST SP 800-171 self-assessment
must be completed and documented. Use the risk-assessment-template.md
as the starting point. Estimated effort: 1–2 weeks with engineering input.
| Milestone | Status | Date |
|---|---|---|
| GCP organization created | ✅ Done | 2025 |
| Cytognosis BAA with Google accepted | ✅ Done | 2025-09-01 |
| GCP project structure (infra / phi-prod / phi-staging / phi-dev / data) | ✅ Done | 2025 |
| Audit log sinks configured (both projects) | ✅ Done | 2026-05-18 |
| 7-year audit log retention locked (irrevocable) | ✅ Done | 2026-05-22 |
| Service account consolidation + least-privilege | ✅ Done | 2026-05 |
| HIPAA SOPs authored (9 documents) | ✅ Done | 2026-05 |
| NIST 800-171 self-assessment | ⏳ Pre-first DUC | TBD |
| Privacy Officer appointed | ⏳ Q3 2026 | TBD |
| First HIPAA training cycle | ⏳ Q3 2026 | TBD |
| VPC Service Controls perimeter | ⏳ Trigger: first external PHI | TBD |
| CMEK on PHI buckets | ⏳ Trigger: first DUC data ingest | TBD |
| First DR tabletop exercise | ⏳ Q1 2027 | TBD |
| Role | Person | Contact |
|---|---|---|
| HIPAA Security Officer | Shahin Mohammadi | mohammadi@cytognosis.org |
| HIPAA Privacy Officer | (to be appointed) | — |
| HIPAA Compliance Officer | (to be appointed) | — |
*This document is reviewed quarterly. Any new vendor engagement, architecture change,
or data classification event may require an out-of-cycle review.*